peter bassill · operator
$ cve CVE-2010-5285 JSON

CVE-2010-5285 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 1.3% (pctl 70)

Patch early

A public exploit exists.

Description

Cross-site request forgery (CSRF) vulnerability in admin.php in Collabtive 0.6.5 allows remote attackers to hijack the authentication of administrators for requests that add administrative users via the edituser action.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS1.33% — more likely to be exploited than 70% of all CVEs
WeaknessCWE-352
On CISA KEVno
Public exploityes
Published2012-11-26
Last modified2026-06-16

Affected (1)

VendorProduct
o-dyncollabtive

Public exploits

SourceTitleDate
exploit-dbCollabtive 0.65 - Multiple Vulnerabilities2010-10-12

References

→ the Explorer  ·  watch your stack  ·  NVD